Information Security Engineer

NVIDIA NVIDIA · Semiconductors · CA +5 · Remote

Information Security Engineer at NVIDIA, focused on hardening products and services, and improving the software development lifecycle. The role involves partnering with engineering and product management, running security reviews, and building automation to enhance secure practices. Requires hands-on experience with AI coding assistants and a strong understanding of application and product security.

What you'd actually do

  1. Constantly improve automation, develop new tools and skills that make our secure practices easier for users to adopt and deploy
  2. Partner with engineering and product management from earliest design through release. This entails tracking evolving discussions, surfacing security implications, and translating them into practical mentorship.
  3. Run security reviews across code, dependencies, containers, cloud, and CI/CD. Triage, prioritize, and drive remediation to closure.
  4. Build automation and developer-facing tooling that make secure-by-default the easy path.
  5. Ask sharp questions. Challenge assumptions. Surface risks that don't appear on standard checklists.

Skills

Required

  • 5+ years of experience in application security, product security, cloud security, infrastructure security, or related security engineering work.
  • Hands-on proficiency with AI coding assistants (Claude, Codex, Cursor, Codeium, Perplexity, or equivalent) in real production work, not experimentation.
  • Proven ability to think critically, creatively, and abstractly about technical systems and contribute useful security perspectives before all details are fully defined.
  • Proactive, fast paced operating style.
  • Strong understanding of secure software development practices and common vulnerability classes.
  • Hands-on experience with at least one major programming or scripting language such as Python, Go, JavaScript, TypeScript, Java, or C++.
  • Familiarity with cloud platforms, containerized workloads, CI/CD pipelines, Linux systems, and modern developer tooling.
  • Clear communicator. Collaborates well with engineers and PMs.

Nice to have

  • Experience building security automation or developer-facing security tools.
  • Familiarity with Kubernetes, Terraform, GitLab/GitHub CI, or cloud-native security controls.
  • Experience with compliance, secure development lifecycle programs, or release security gates.
  • Background in threat modeling, design review, incident analysis, vulnerability research, or systems thinking.
  • Ability to connect technical details to broader organizational, product, or operational risk.

What the JD emphasized

  • Hands-on proficiency with AI coding assistants (Claude, Codex, Cursor, Codeium, Perplexity, or equivalent) in real production work, not experimentation.
  • We'll ask how these tools have changed how you build, review, and secure code.